Penetration Testing Process & Methodology
CPTS · 25 questions
- A county CIO asks what a letter of engagement is supposed to lock in before any scanning starts. What should the tester treat as the primary purpose of that letter?
- A city attorney objects to a municipal pentest scoped as 'test everything on the network.' Why is that scope statement a professional risk?
- A water-utility board treats a vulnerability assessment and a full penetration test as the same deliverable. What distinction should the tester emphasize?
- A library consortium assumes staff LinkedIn OSINT is automatically in scope for a municipal web engagement. What is the sound professional stance?
- A transit IT lead requires that all active testing occur only after hours. How should that requirement be handled?
- A school district's rules of engagement forbid intentional denial-of-service during the assessment. A tester finds a path that would likely crash a critical student portal. What is the correct action?
- A mayor's office asks who can authorize a penetration test against city systems. Which answer is professionally correct?
- A parks department requests 'black box' external testing but provides full network diagrams on day one. What should the tester recognize?
- A municipal SOC asks for the high-level stages of a professional penetration test in sound order. Which sequence best reflects standard methodology flow?
- A county assessor asks why enumeration is not the same as exploitation during a CPTS-style engagement. What is the clearest distinction?
- A civic open-data portal engagement is scoped as web-application testing only, but a tester begins port-scanning the entire municipal /16. What problem does that create?
- A city grants VPN access for an Active Directory-focused internal assessment. How should the tester characterize the starting posture?
- A utility CISO asks what threat-landscape-driven testing means compared with only hunting famous CVEs. Which statement best captures the CPTS-style emphasis?
- A township requires immediate notification if critical findings appear during testing. How should the tester treat that expectation?
- A court IT manager frames success as 'get in and root everything,' while the engagement objective is protecting case data. What should the tester reinforce?
- A new hire wonders why careful note-taking matters before any exploit attempt on a municipal engagement. What is the best reason?
- A municipal team asks the tester to change production firewall rules mid-engagement 'to help secure them.' What is the appropriate response?
- A city procurement officer asks why a letter of engagement and report expectations appear at kickoff. What is the best explanation?
- A county asks whether skipping fundamentals on a training path is fine before a client engagement. What readiness stance should guide the answer?
- A library IT lead asks how lab reset habits differ from caution on a production municipal network. Which contrast is accurate?
- A public-health agency asks who owns residual risk after the penetration test findings are delivered. Who owns that decision?
- A city wants one commercial tool that will 'do the whole pentest' without further methodology. What should the tester explain?
- A transit security manager asks why legal and ethical boundaries still apply after a contract is signed. What is the right framing?
- A municipal PMO asks when reporting work should start during a multi-week penetration test. What timing is preferred?
- A county board asks what a commercial-grade penetration test report implies beyond a list of CVE IDs. Which answer best fits?